Self-hosting

Updated

The management dashboard and the four product APIs. Images come from the private registry named in your registry-access email (<registry-host>/docker/kryptic/<name>:<tag>). Docs, the public site, Public API, and Internal API are not in this stack.

Self-hosting requires a Business or Enterprise licence key. There is no free self-hosted tier. If you are still evaluating, try Kryptic on a cloud plan first.

Your registry-access email has:

FieldWhere you put it
Registry hostdocker login, --docker-server, and DOCKER_REGISTRY (<host>/docker)
Helm repo URLhelm repo add kryptic <url>
Username + the password you setdocker login or helm repo add, and the image pull secret
Image tagKRYPTIC_VERSION in .env or Helm values
Helm chart versionhelm install --version
Air-gap bundle linkdocker load on offline hosts, see Air-gapped

The attached kryptic-selfhost.zip has Compose, .env.example, up.sh, values.example.yaml, and the Helm chart (kryptic-helm-<version>.tgz). The same email links the air-gap image tarball, downloadable with your registry credentials. See Air-gapped.

Pick an install path:

Keys, URLs, Postgres, and upgrades are in Settings and options.

Create your organization

After the stack is up, open the dashboard and register the first organization. There is no confirmation email. Then initialize encryption under Settings → Encryption before anyone stores secrets. Invite your team. Point developer daemons at your deployment:

kryptic config set-api https://daemon.kryptic.example.com
kryptic login

KRYPTIC_API overrides the saved URL without writing it. Changing the saved URL signs you out, because tokens belong to one server.

CI runners use KRYPTIC_PIPELINES_API with kryptic ci export.